Cloud Security Authors: Rostyslav Demush, Elizabeth White, John Katrick, Pat Romanski, Yeshim Deniz

Related Topics: @CloudExpo, Cloud Security, Government Cloud

@CloudExpo: Article

Is Cloud Computing for Real?

Summary of Session by CIO of the National Reconnaissance Office at Cloud Expo New York

In October 2009, Enterprise Cloud Computing was considered bleeding edge technology by many but there was something that seemed different about its value potential and adoption rate. For CIOs, it seemed a chance to provision affordable infrastructure quickly, alleviating delays to mission critical deliveries. Federal CIOs interest in Enterprise Cloud Computing was limited to innovators and early adopters. Two years later, where does Enterprise Cloud Computing stand? Is it for real?

Today, Cloud Computing is on the Gartner® technology hype curve in the “peak of inflated expectations” category. Its placement on the curve—even though we all should prepare for the dreaded “trough of disillusionment” dip—indicates Cloud Computing is, indeed, for real. There are other indicators of note also. CIOs across the board are focused on the success Cloud Computing can deliver. Vendors are sparring with each other to obtain space in Gartner’s Magic Quadrant. The Federal CIO has issued a “Cloud First” policy and published the first Federal Cloud Computing Strategy. And, it’s been featured in the hit comic strip Dilbert—a pop culture indicator worth noting!

Federal agencies need IT solutions that can handle current missions—from supporting counter-terrorism to combating proliferation of weapons of mass destruction--and we need IT that can handle global surge demands based on fluctuating world events and natural disasters. Federal IT must be efficiently adaptable and properly affordable to meet evolving mission needs. It must be capable of keeping pace with the exponential growth of data, including the increasing complexities of maintaining legal and regulatory compliance of information management and assurance.

As a CIO, building your cloud strategy can be confusing as there are many options to consider before making a decision. Cloud Computing can deliver within a variety of characteristics. Each CIO will need to consider the characteristics of primary importance in order to properly center a strategy. For example, determining your needs for rapid elasticity, on-demand self-service, global access, and payment options will be necessary to develop the right strategy. The second consideration for a CIO is just how far up the stack she wants to go. Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) each deliver different features and capabilities for your business. You can develop a plan that includes some or all of the Services. Finally, a CIO needs to think about the deployment model(s) that best fit her business (Public, Private, Community, and Hybrid).

Cloud Computing isn’t perfect; there are concerns to manage and mistakes to avoid. The number one concern remains Security and that’s given rise to Enterprise Cloud Computing deployments and private clouds. But, there are other concerns also such as the skill set of your workforce, requirements for compliance verification, legacy baseline migration, and costs. For example, depending on the percentage of your legacy that can successfully transition to Cloud, your cost-benefit equation may not provide sufficient return for the investment.

Common mistakes to avoid include: assuming Cloud Computing is for everything; planning for a “light switch” migration from legacy to new; selecting only one vendor and creating early lock-in; underestimating the cultural change required by your own IT team; and implementing a bunch of mini- clouds in your existing data closets.

We’ve spent 18 months developing the National Reconnaissance Office (NRO) IT strategy and roadmap; we gave it a lot of thought but it is just an example and not the only way to move forward. Our cloud delivery model will be private first and then a hybrid of private and community (with our Intelligence Community colleagues). We’re moving our way up the stack starting with IaaS and PaaS first, then SaaS. And, we are focused on a phased revolutionary approach—building a new environment as a green field.

Our planning has highlighted the need to focus attention on management of the NRO Cloud. Defining specific roles and responsibilities, articulating cloud service level agreements between the provider and users, adjusting organizational constructs to fit the Cloud business model, and streamlining configuration control processes to meet the rapid timelines of provisioning must all be addressed if success is to be achieved. Our planning also indicated the NRO mission would not be served by a CPU-based commodity cloud alone. We also need a high-performance cloud that is GPU-based and we are learning there are industry gaps in this area.

The NRO Cloud strategy won’t be too different from how other Federal agencies adopt Cloud Computing. Most agencies processing classified information are focused on private clouds versus public clouds for security and information management/assurance reasons. Over time, though, I believe federal community clouds will emerge, as will private hybrid clouds, which allow agencies to maintain a private space as well as take advantage of federal community clouds.

The NRO Cloud will be implemented in four phases over the course of 6 years. It’s a complex migration necessarily paced to meet federal budget processes, existing acquisition commitments, and mission service imperatives.

  • Phase 1 – Test It. We have multiple small cloud pilots ongoing covering commodity/utility cloud, high performance cloud, and big data cloud. We are focused on streamlining information assurance compliance, developing appropriate policies and processes, and defining standards.
  • Phase 2 – Prove It. In this phase, we will merge successful elements from Phase 1, finalize policies, prototype management and governance changes necessary for cloud provisioning models, refine standards, realign programs as needed, and ensure enterprise foundation capabilities meet mission demands.
  • Phase 3 – Use It. Scaled deployment of the enterprise Cloud will occur. Applications will develop specific transition and migration plans generally aligned with planned refresh cycles. Service management processes and new centralized information assurance approaches will be refined for long-term success.
  • Phase 4 – Exploit It. The NRO Cloud will emerge as the primary Enterprise Infrastructure Services Provider with robust measures of effectiveness, performance accountability, and service transparency. New mission and business applications will emerge through innovations in Cloud Computing and federation with the IC Cloud will be achieved moving the NRO into a hybrid environment.

In summary, the time for Cloud Computing is now. All of the indicators are in place to suggest a rapid and successful migration to this newest generation of IT architecture. It is not a one-size-fits-all migration. CIOs will need to spend time exploring Cloud Computing solutions to find the combination that best responds to specific mission and business needs. Maintaining awareness of the concerns and mistakes is absolutely necessary and security remains the top concern. Security is a huge focus for IT vendors and creative, robust solutions will be constantly emerging to reduce concerns. Large organizations will increasingly turn to Enterprise Cloud Computing strategies to achieve efficiencies of Cloud Computing while reducing risks of exposure for intellectual property, customer privacy, and competitive strategies.

More Stories By Jill Tummler Singer

Jill Tummler Singer is CIO for the National Reconnaissance Office (NRO)- which as part of the 16-member Intelligence Community plays a primary role in achieving information superiority for the U.S. Government and Armed Forces. A DoD agency, the NRO is staffed by DoD and CIA personnel. It is funded through the National Reconnaissance Program, part of the National Foreign Intelligence Program.

Prior to joining the NRO, Singer was Deputy CIO at the Central Intelligence Agency (CIA), where she was responsible for ensuring CIA had the information, technology, and infrastructure necessary to effectively execute its missions. Prior to her appointment as Deputy CIO, she served as the Director of the Diplomatic Telecommunications Service (DTS), United States Department of State, and was responsible for global network services to US foreign missions.

Singer has served in several senior leadership positions within the Federal Government. She was the head of Systems Engineering, Architecture, and Planning for CIA's global infrastructure organization. She served as the Director of Architecture and Implementation for the Intelligence Community CIO and pioneered the technology and management concepts that are the basis for multi-agency secure collaboration. She also served within CIA’s Directorate of Science and Technology.

Comments (1)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.

@ThingsExpo Stories
Cloud-enabled transformation has evolved from cost saving measure to business innovation strategy -- one that combines the cloud with cognitive capabilities to drive market disruption. Learn how you can achieve the insight and agility you need to gain a competitive advantage. Industry-acclaimed CTO and cloud expert, Shankar Kalyana presents. Only the most exceptional IBMers are appointed with the rare distinction of IBM Fellow, the highest technical honor in the company. Shankar has also receive...
Enterprises have taken advantage of IoT to achieve important revenue and cost advantages. What is less apparent is how incumbent enterprises operating at scale have, following success with IoT, built analytic, operations management and software development capabilities - ranging from autonomous vehicles to manageable robotics installations. They have embraced these capabilities as if they were Silicon Valley startups.
DXWorldEXPO LLC announced today that ICOHOLDER named "Media Sponsor" of Miami Blockchain Event by FinTechEXPO. ICOHOLDER give you detailed information and help the community to invest in the trusty projects. Miami Blockchain Event by FinTechEXPO has opened its Call for Papers. The two-day event will present 20 top Blockchain experts. All speaking inquiries which covers the following information can be submitted by email to [email protected] Miami Blockchain Event by FinTechEXPO also offers s...
Poor data quality and analytics drive down business value. In fact, Gartner estimated that the average financial impact of poor data quality on organizations is $9.7 million per year. But bad data is much more than a cost center. By eroding trust in information, analytics and the business decisions based on these, it is a serious impediment to digital transformation.
Predicting the future has never been more challenging - not because of the lack of data but because of the flood of ungoverned and risk laden information. Microsoft states that 2.5 exabytes of data are created every day. Expectations and reliance on data are being pushed to the limits, as demands around hybrid options continue to grow.
The standardization of container runtimes and images has sparked the creation of an almost overwhelming number of new open source projects that build on and otherwise work with these specifications. Of course, there's Kubernetes, which orchestrates and manages collections of containers. It was one of the first and best-known examples of projects that make containers truly useful for production use. However, more recently, the container ecosystem has truly exploded. A service mesh like Istio addr...
As IoT continues to increase momentum, so does the associated risk. Secure Device Lifecycle Management (DLM) is ranked as one of the most important technology areas of IoT. Driving this trend is the realization that secure support for IoT devices provides companies the ability to deliver high-quality, reliable, secure offerings faster, create new revenue streams, and reduce support costs, all while building a competitive advantage in their markets. In this session, we will use customer use cases...
Digital Transformation: Preparing Cloud & IoT Security for the Age of Artificial Intelligence. As automation and artificial intelligence (AI) power solution development and delivery, many businesses need to build backend cloud capabilities. Well-poised organizations, marketing smart devices with AI and BlockChain capabilities prepare to refine compliance and regulatory capabilities in 2018. Volumes of health, financial, technical and privacy data, along with tightening compliance requirements by...
Business professionals no longer wonder if they'll migrate to the cloud; it's now a matter of when. The cloud environment has proved to be a major force in transitioning to an agile business model that enables quick decisions and fast implementation that solidify customer relationships. And when the cloud is combined with the power of cognitive computing, it drives innovation and transformation that achieves astounding competitive advantage.
DevOpsSummit New York 2018, colocated with CloudEXPO | DXWorldEXPO New York 2018 will be held November 11-13, 2018, in New York City. Digital Transformation (DX) is a major focus with the introduction of DXWorldEXPO within the program. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of bus...
Cloud Expo | DXWorld Expo have announced the conference tracks for Cloud Expo 2018. Cloud Expo will be held June 5-7, 2018, at the Javits Center in New York City, and November 6-8, 2018, at the Santa Clara Convention Center, Santa Clara, CA. Digital Transformation (DX) is a major focus with the introduction of DX Expo within the program. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive ov...
DXWordEXPO New York 2018, colocated with CloudEXPO New York 2018 will be held November 11-13, 2018, in New York City and will bring together Cloud Computing, FinTech and Blockchain, Digital Transformation, Big Data, Internet of Things, DevOps, AI, Machine Learning and WebRTC to one location.
DXWorldEXPO | CloudEXPO are the world's most influential, independent events where Cloud Computing was coined and where technology buyers and vendors meet to experience and discuss the big picture of Digital Transformation and all of the strategies, tactics, and tools they need to realize their goals. Sponsors of DXWorldEXPO | CloudEXPO benefit from unmatched branding, profile building and lead generation opportunities.
Dion Hinchcliffe is an internationally recognized digital expert, bestselling book author, frequent keynote speaker, analyst, futurist, and transformation expert based in Washington, DC. He is currently Chief Strategy Officer at the industry-leading digital strategy and online community solutions firm, 7Summits.
Digital Transformation and Disruption, Amazon Style - What You Can Learn. Chris Kocher is a co-founder of Grey Heron, a management and strategic marketing consulting firm. He has 25+ years in both strategic and hands-on operating experience helping executives and investors build revenues and shareholder value. He has consulted with over 130 companies on innovating with new business models, product strategies and monetization. Chris has held management positions at HP and Symantec in addition to ...
With 10 simultaneous tracks, keynotes, general sessions and targeted breakout classes, @CloudEXPO and DXWorldEXPO are two of the most important technology events of the year. Since its launch over eight years ago, @CloudEXPO and DXWorldEXPO have presented a rock star faculty as well as showcased hundreds of sponsors and exhibitors! In this blog post, we provide 7 tips on how, as part of our world-class faculty, you can deliver one of the most popular sessions at our events. But before reading...
The best way to leverage your Cloud Expo presence as a sponsor and exhibitor is to plan your news announcements around our events. The press covering Cloud Expo and @ThingsExpo will have access to these releases and will amplify your news announcements. More than two dozen Cloud companies either set deals at our shows or have announced their mergers and acquisitions at Cloud Expo. Product announcements during our show provide your company with the most reach through our targeted audiences.
The IoT Will Grow: In what might be the most obvious prediction of the decade, the IoT will continue to expand next year, with more and more devices coming online every single day. What isn’t so obvious about this prediction: where that growth will occur. The retail, healthcare, and industrial/supply chain industries will likely see the greatest growth. Forrester Research has predicted the IoT will become “the backbone” of customer value as it continues to grow. It is no surprise that retail is ...
Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life settlement products to hedge funds and investment banks. After, he co-founded a revenue cycle management company where he learned about Bitcoin and eventually Ethereal. Andrew's role at ConsenSys Enterprise is a mul...
DXWorldEXPO LLC announced today that "Miami Blockchain Event by FinTechEXPO" has announced that its Call for Papers is now open. The two-day event will present 20 top Blockchain experts. All speaking inquiries which covers the following information can be submitted by email to [email protected] Financial enterprises in New York City, London, Singapore, and other world financial capitals are embracing a new generation of smart, automated FinTech that eliminates many cumbersome, slow, and expe...